← Rōvn home
Compliance status

What is in place. What is in progress. What is pending.

This is Rōvn's living public compliance snapshot. We update it as evidence is added or status changes. Sales is not allowed to claim more than what is on this page. Customers and prospective investors can request the underlying evidence binder under NDA.

HIPAA program

Control areaStatusEvidence
AWS Business Associate Addendum (BAA) accepted on Rōvn accountIn placeAWS Artifact
HIPAA-eligible AWS foundation (private VPC, KMS, CloudTrail, GuardDuty, Security Hub, AWS Backup)In placeEvidence binder · AWS console screenshots
RDS PHI Postgres (private, encrypted, deletion protection, backup policy)In placerovn-prod-phi-postgres
Backup + verified restore drillIn placeRestore evidence in PHI evidence vault
Nurse consent ledger + signed packet release eventsIn placeMigration 017_rovn_ready_requirements_evidence.sql
Formal HIPAA Security Risk AssessmentIn progressTarget: pre-PHI prod cutover
Vendor BAA / DPA inventory and signed sub-processor agreementsIn progressAWS, Persona, Checkr, NPDB, Nursys + others
Formal HIPAA policies (privacy, security, breach, sanctions, training)In progressWorkforce acknowledgements pending
Quarterly access review evidenceIn progressFirst review scheduled
Incident response runbook + tabletop exerciseIn progressFirst tabletop scheduled
Production secrets fully migrated to Secrets Manager / SSMIn progressMigration in flight
Reviewed production application image in ECR + ECS service enabledPending reviewECS desired count 0 by design
Production traffic connected to PHI backendPendingWill not enable until program above is complete
Independent third-party HIPAA assessmentPlannedPost-Series-A
SOC 2 Type I readinessPlannedVendor selected after first paying facilities

Verification and credentialing data

CapabilityStatusSource
NPDB registrationRegisteredDBID 399700000147857 · pending notarized doc upload
Nursys e-NotifyLivee-Notify production
OIG / SAM exclusion screeningIn placeContinuous screening
Identity verification (Persona)In integrationVendor BAA tracked
Background check (Checkr)In integrationVendor agreement tracked
State BON primary-source queryIn progressPer-state coverage tracked

Privacy and consumer rights

Asks under NDA

Customers and qualified investors can request:

Send the request to security@rovn.to.

Last updated 2026-04-25. Owner: Rovn LLC, CEO Giles-Evan Mboumi.